Toward a Principled Framework for Disclosure Avoidance

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Hawes, Michael B, Brassell, Evan M, Caruso, Anthony, Cumings-Menon, Ryan, Devine, Jason, Dorius, Cassandra, Evans, David, Haase, Kenneth, Hedrick, Michele C, Krause, Alexandra, Leclerc, Philip, Livsey, James, Rodriguez, Rolando A, Rogers, Luke T, Spence, Matthew, Velkoff, Victoria, Walsh, Michael, Whitehorne, James, Keller, Sallie Ann
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908497908596736
author Hawes, Michael B
Brassell, Evan M
Caruso, Anthony
Cumings-Menon, Ryan
Devine, Jason
Dorius, Cassandra
Evans, David
Haase, Kenneth
Hedrick, Michele C
Krause, Alexandra
Leclerc, Philip
Livsey, James
Rodriguez, Rolando A
Rogers, Luke T
Spence, Matthew
Velkoff, Victoria
Walsh, Michael
Whitehorne, James
Keller, Sallie Ann
author_facet Hawes, Michael B
Brassell, Evan M
Caruso, Anthony
Cumings-Menon, Ryan
Devine, Jason
Dorius, Cassandra
Evans, David
Haase, Kenneth
Hedrick, Michele C
Krause, Alexandra
Leclerc, Philip
Livsey, James
Rodriguez, Rolando A
Rogers, Luke T
Spence, Matthew
Velkoff, Victoria
Walsh, Michael
Whitehorne, James
Keller, Sallie Ann
contents Responsible disclosure limitation is an iterative exercise in risk assessment and mitigation. From time to time, as disclosure risks grow and evolve and as data users' needs change, agencies must consider redesigning the disclosure avoidance system(s) they use. Discussions about candidate systems often conflate inherent features of those systems with implementation decisions independent of those systems. For example, a system's ability to calibrate the strength of protection to suit the underlying disclosure risk of the data (e.g., by varying suppression thresholds), is a worthwhile feature regardless of the independent decision about how much protection is actually necessary. Having a principled discussion of candidate disclosure avoidance systems requires a framework for distinguishing these inherent features of the systems from the implementation decisions that need to be made independent of the system selected. For statistical agencies, this framework must also reflect the applied nature of these systems, acknowledging that candidate systems need to be adaptable to requirements stemming from the legal, scientific, resource, and stakeholder environments within which they would be operating. This paper proposes such a framework. No approach will be perfectly adaptable to every potential system requirement. Because the selection of some methodologies over others may constrain the resulting systems' efficiency and flexibility to adapt to particular statistical product specifications, data user needs, or disclosure risks, agencies may approach these choices in an iterative fashion, adapting system requirements, product specifications, and implementation parameters as necessary to ensure the resulting quality of the statistical product.
format Preprint
id arxiv_https___arxiv_org_abs_2502_07105
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Toward a Principled Framework for Disclosure Avoidance
Hawes, Michael B
Brassell, Evan M
Caruso, Anthony
Cumings-Menon, Ryan
Devine, Jason
Dorius, Cassandra
Evans, David
Haase, Kenneth
Hedrick, Michele C
Krause, Alexandra
Leclerc, Philip
Livsey, James
Rodriguez, Rolando A
Rogers, Luke T
Spence, Matthew
Velkoff, Victoria
Walsh, Michael
Whitehorne, James
Keller, Sallie Ann
Applications
Computers and Society
Responsible disclosure limitation is an iterative exercise in risk assessment and mitigation. From time to time, as disclosure risks grow and evolve and as data users' needs change, agencies must consider redesigning the disclosure avoidance system(s) they use. Discussions about candidate systems often conflate inherent features of those systems with implementation decisions independent of those systems. For example, a system's ability to calibrate the strength of protection to suit the underlying disclosure risk of the data (e.g., by varying suppression thresholds), is a worthwhile feature regardless of the independent decision about how much protection is actually necessary. Having a principled discussion of candidate disclosure avoidance systems requires a framework for distinguishing these inherent features of the systems from the implementation decisions that need to be made independent of the system selected. For statistical agencies, this framework must also reflect the applied nature of these systems, acknowledging that candidate systems need to be adaptable to requirements stemming from the legal, scientific, resource, and stakeholder environments within which they would be operating. This paper proposes such a framework. No approach will be perfectly adaptable to every potential system requirement. Because the selection of some methodologies over others may constrain the resulting systems' efficiency and flexibility to adapt to particular statistical product specifications, data user needs, or disclosure risks, agencies may approach these choices in an iterative fashion, adapting system requirements, product specifications, and implementation parameters as necessary to ensure the resulting quality of the statistical product.
title Toward a Principled Framework for Disclosure Avoidance
topic Applications
Computers and Society
url https://arxiv.org/abs/2502.07105